Research

What we think, and
what it is based on.

Briefs and position papers on AI governance, continuous assurance, and how security organizations are being restructured around both. Sources are cited. Read them as arguments: if one does not hold up against your environment, it has failed its job.


Brief 01 · Industry data

Adoption isn't the gap.
Restructuring is.

Full brief, 4 pages, PDF →
Chart of AI adoption across every US business. 100 dots, each representing about 330,000 businesses. 81 percent have not adopted AI, 19 percent have adopted AI, 4.4 percent are running AI agents, and 0.95 percent have restructured around AI agents.

Almost every company is counted as an AI adopter on the strength of a purchase. Buying a model is not an operating change, and the numbers separate cleanly once you ask how far a business actually got.

81%
have not adopted AI at all
19%
adopted AI, meaning they bought a model
4.4%
are running agents in the loop
0.95%
restructured the work around those agents

The last row is the one that matters. Under one percent of US businesses have turned their core functions into governed code and let agents run them end to end. That is the group pulling ahead, and it is the group that needs an assurance model built for machine-speed change.

Sources: Goldman Sachs AI Adoption Tracker (March 2026); Deloitte, State of AI in the Enterprise (2026). Counts are approximate and reflect the furthest stage reached. The framing is our reading of the published figures, not the publishers'.


Brief 02 · The security function

The CISO org, re-drawn.

Download, 1 page, PDF →

Security organizations are still drawn around the tools they bought. AppSec, Cloud Security, SOC, GRC, Identity: five teams that mirror five product categories. It worked while humans did the work at human speed. It stops working when a large share of the change is machine-authored, because the failure modes no longer respect those boundaries.

Two security org charts side by side. Today, organized around functions: AppSec, Cloud Security, SOC, GRC, and Identity and Access. Future, organized around outcomes: Security Strategy and Risk, AI and Automation Engineering, Security Operations (Platform), Engineering Enablement, and Trust and Business Resilience. A bottom band maps each outcome pillar to a matching as-code capability.
From functions to outcomes. Each pillar on the right maps to an as-code capability rather than to a product category.

What changes

The right-hand org is not a rename. Ownership moves from "who runs this tool" to "who is accountable for this outcome," which is the only framing that survives having agents inside the workflow. Engineering Enablement exists because secure-by-design is a developer experience problem. AI and Automation Engineering exists because someone has to own agent operations before it owns you.

Why it is here

We publish this because it is the argument underneath the product, and it should be judged on its own. If the outcome-shaped org is wrong, then continuous assurance is a solution to a problem you do not have. If it is right, the tooling has to change to match, and that is the part we build.


Position papers

Eight papers, in full.

Longer-form arguments on GRCDevSecOps, continuous monitoring, and the architecture behind continuous assurance. All free, no form, no email gate.

Browse the papers